5.4
CVE-2023-3580
- EPSS 0.09%
- Veröffentlicht 10.07.2023 16:15:56
- Zuletzt bearbeitet 21.11.2024 08:17:35
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squidex.Io ≫ Squidex Version < 7.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.249 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
| security@huntr.dev | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-167 Improper Handling of Additional Special Element
The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.